Skip to content

WindowsTechs.com

Collaborate Disseminate

Menu

Primary menu

  • Home

Author Archives: Melab

TCG Opal/Pyrite-like storage but without PSID reversion

Posted on September 20, 2026 by Melab

I asked if there was a specific industry term for untrusted storage that has its data integrity tracked using smaller, trusted storage. Self-encrypting drives got mentioned in the comments as an alternative. I rejected it at first because … Continue reading TCG Opal/Pyrite-like storage but without PSID reversion→

Posted in opal-2.0

Conventional term for integrity-tracked storage

Posted on September 3, 2026 by Melab

I’m thinking of a scheme wherein there is a secure element with trusted storage (e.g., non-tamperable on-chip NVRAM) paired operating in conjunction with untrusted storage (e.g., any kind of mass storage like a hard drive, SSD, magnetic ta… Continue reading Conventional term for integrity-tracked storage→

Posted in integrity, Secure Enclave, tamper-resistance

Anti-rollback signing with TPM 2.0

Posted on June 30, 2026 by Melab

Correct me if I’m wrong, but seems to me that by using TPM2_PolicyNV one can create an NVRAM slot whose value can only updated to something greater than its current contents. In contrast to using a TPMA_NV_COUNTER-type NVRAM slot, this all… Continue reading Anti-rollback signing with TPM 2.0→

Posted in TPM

Authenticating a TPM

Posted on May 25, 2026 by Melab

Suppose that we have a secure/trusted system that communicates with a TPM and we want to ensure two things:

The TPM hasn’t been replaced.
The TPM is under the same ownership "session", i.e., new ownership hasn’t been taken.

How… Continue reading Authenticating a TPM→

Posted in TPM

Authenticating a TPM

Posted on May 25, 2026 by Melab

Suppose that we have a secure/trusted system that communicates with a TPM and we want to ensure two things:

The TPM hasn’t been replaced.
The TPM is under the same ownership "session", i.e., new ownership hasn’t been taken.

How… Continue reading Authenticating a TPM→

Posted in TPM

Creating a TPM 2.0 NVRAM that requires signature and password to be modified

Posted on May 20, 2026 by Melab

With TPM 1.2, the access controls for a NVRAM slots were simple and straightforward. TPM 2.0, by contrast, allows for more complex controls, but these aren’t straightforward. I am using IBM’s tpm2-tools for this task and the documentation … Continue reading Creating a TPM 2.0 NVRAM that requires signature and password to be modified→

Posted in TPM

TPM "Reset" versus "Restart" [closed]

Posted on May 14, 2026 by Melab

TPM specifications say that TPM_NV_WRITE_STCLEAR and TPM_NV_GLOBALLOCK permissions mean an NVRAM slot can be locked until the next "TPM Reset" or the next "TPM Restart". But what is the difference between "Restart&… Continue reading TPM "Reset" versus "Restart" [closed]→

Posted in TPM

Difference between platform and owner passwords in TPM 2.0

Posted on January 9, 2025 by Melab

There is a password for the owner hierarchy and there is a password for the platform hierarchy in the TPM 2.0 specification. What is the difference what can either do that the other cannot? How do their purposes and uses differ?

Continue reading Difference between platform and owner passwords in TPM 2.0→

Posted in TPM

Create a password policy for TPM 2.0

Posted on January 5, 2025 by Melab

For an NVRAM slot, I would like to create a TPM 2.0 policy that uses TPM2_PolicyPassword. I assume that tpm2_policypassword is the tool to use to create such a policy, but the man page doesn’t tell me how to specify the desired password. H… Continue reading Create a password policy for TPM 2.0→

Posted in TPM

What is in a TPM policy?

Posted on November 22, 2024 by Melab

Documentation for the tpm2_nvdefine utility mentions using a policy to control access to NVRAM areas.

-L, –policy=FILE:
Specifies the policy digest file for policy based authorizations.

What do these policies look like? How are they enf… Continue reading What is in a TPM policy?→

Posted in TPM

Post navigation

← Older posts

Primary Sidebar Widget Area

Infocon Status

Internet Storm Center Infocon Status

Recent Posts

  • RatHat Android Trojan Uses AI for Automation September 21, 2026
  • Fastly gives enterprises real-time control over AI models and agents September 21, 2026
  • North Korea’s job interview scam runs both ways September 21, 2026
  • Google hit with €403 million GDPR fine over location tracking September 21, 2026
  • Rust Team Members and Popular Crate Owners Targeted via Video Calls September 21, 2026

Tag Cloud

Agriculture Alzheimer's Disease Art Audio Automation Bluetooth Building and Construction Campervan Camping Cancer Coronavirus (COVID-19) Cycling Dementia Diabetes DNA Electric Vehicles Food Home House Huawei Indiegogo MIT Mobility Moon New Atlas Audio NVIDIA Off-grid Off-road Pedal-assisted Photography Physics Radio Repair RV Samsung Satellite Sony SpaceX spoofing sustainable design The Immune System Tiny Footprint Training Water Zoom

Archives

  • Facebook
  • Twitter
  • Linkedin
  • Email
Copyright © 2026 WindowsTechs.com. All Rights Reserved.
Theme: Catch Box by Catch Themes
Scroll Up